Threat modeling must identify business assets, their value, and likely adversary motivations to focus testing on what matters to the client rather than what is easy to attack.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.